Open Source · · 1 day
Prebid npm packages carried Qix wallet drainer
Prebid.js and Prebid Universal Creative npm releases were briefly compromised during the September 2025 npm phishing wave. The affected packages carried crypto-transaction redirection malware.
Part of Qix phishing shipped wallet drainers campaign
Prebid was one of the browser-facing follow-on surfaces in the September 2025 npm phishing wave. GitHub advisories and ecosystem databases identified malicious releases for prebid.js 10.9.2 and prebid-universal-creative 1.17.3, separate from the original Qix maintainer package set and the later DuckDB cluster.
The placement mattered. Prebid packages are used in advertising workflows that can reach production browser bundles, so a wallet-drainer payload did not need server persistence to create risk. If the malicious package was built into client-side code, it could run where users, wallets, and transaction prompts meet.
The shared campaign code targeted cryptocurrency activity. Reporting tied the family to web3 transaction monitoring and destination-address replacement, turning a normal dependency update into a possible payment-redirection path.
This record keeps the Prebid package coordinates together because the exposure query is package-specific: look for [email protected] and [email protected] in lockfiles, build caches, private mirrors, and deployed bundles. The parent campaign record carries the phishing infrastructure and wider Qix wallet-drainer context.
Notes
- An indicator recorded here gave the SHA-256 of a zero-byte file as the digest of the compromised tarball, so a failed or empty download had been recorded as evidence. It has been removed. The digest on the artifact itself is unaffected.
Appendix · Affected releases
- GitHub Advisory GHSA-jwq7-6j4r-2f92 describes the affected npm package as Prebid.js 10.9.2.
References
Source record: oss/attacks/prebid-npm/meta.yaml